APT30 is a long-running cyber-espionage threat group active since at least 2004 and widely assessed as likely state-sponsored, with strong indications of Chinese origin or alignment. The group has operated as a professional and cohesive team with structured malware development, target prioritization, and sustained operational planning over many years. Its activity has been closely associated with intelligence collection requirements relevant to China’s regional strategic interests. APT30 has consistently targeted Southeast Asia and India, with particular attention to governments, politically relevant organizations, and media entities covering regional affairs. Reported targeting has aligned with ASEAN summits, territorial disputes, and other political developments involving China, India, and Southeast Asian states. The group’s objective has been the theft of sensitive information, including from government environments and other networks not directly reachable from the public Internet. The actor is known for modular malware and specialized tooling, including the BACKSPACE malware family and supporting tools such as SHIPSHAPE, SPACESHIP, and FLASHFLOOD. Its tradecraft includes long-term persistence, stealth features, multi-stage command-and-control, and tooling that supports infection and data theft from air-gapped or otherwise isolated environments through removable media. APT30 has also demonstrated the ability to relay traffic from the Internet into local networks, improving post-compromise access and collection opportunities. Overall, APT30 is best characterized as a disciplined cyber-espionage operator focused on sustained intelligence collection against South and Southeast Asian targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.